Untitled Deck Flashcards
(183 cards)
Person resonsible for handling the technology elements of testing activities
Technical Contact
party responsible for handling the project on the client’s end.
Primary Contact
This can usually be a CISO or other party responsible for the major decisions surrounding the penetration test.
Detailed explanation of testing steps
Attack narrative
what info is included in Scope section of PTES report?
pre-engagement defined scope of testing
What section of the PTES report shows critical vuln, attack vectors successfully exploited, etc.?
Findings section
Cost-benefit analysis is part of ___?
Client acceptance
Windows - remove any keys or scheduled tasks from…?
HKLM and HKCU
2 tools for Service enumeration
NETCAT AND WGET
An attack surface analyser similar to Shodan
Censys
identify exposed systems
2 tools to create malformed packets
Scapy
Hping3
Open source Server scanner
Nikto
Social engineering attack where the malicious actor communicates with the victim from a supposedly reputable source?
Phishing
When an attacker entices the victim into navigating to a malicious web page that has been set up to look official.
Pharming
Social media site with short statements that promote products
Website enumeration is part of what phase of the pentest process?
Reconn and footprinting
Shodan is used to test…?
IoT devices - index devices
Tool used to index IoT devices?
Shodan
NSE
Nmap Scripting Engine - write custom logic with Lua
Allows enumeration of automation across large IP ranges?
NSE
Nmap scripting engine with custom logic written in Lua
Big picture document
MSA - used to cover recurring costs and unforseen charges.
What we will do, when and for how much is in what document?
SOW
Measurable targets - reason contract can be terminated is in what document?
SLA
API testing is associated with …
Cloud
Document includes reasons a contract can be terminated.
SLA